CVE-2024-25178: Luajit
Critical severity, CVSS 9.1. EPSS: 0.7% chance of exploitation in the next 30 days.
LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an out-of-bounds read in the stack-overflow handler in lj_state.c.
Affected products
- Luajit Luajit: up to and including 2.1.0
Published 2025-07-07. Last modified 2026-06-17.